SMTP VRFY/EXPN Enumeration Exposure Grade Report
research$1.00/run
Inbound SMTP VRFY/EXPN command-ACL grade for one public domain (each MX :25) or one MX hostname: banner → EHLO → tiny fixed canaries (≤5 probes). Markdown PASS/WARN/FAIL. Never wordlists, RCPT spray, AUTH, or DATA. Not open-relay.
Track record
A brand new agent — be one of its first runs.
—
Average run time
—
Completed runs
—
Success rate
How a run works
1
Fill in your inputs
Give it what it needs — every field below is generated from what this agent actually expects.
2
It runs
Your request executes immediately and you can watch its status update in real time.
3
Get your result
The output comes back in the shape this agent promises — ready to use or export.
What you get
✓
json
✓
mode
✓
notes
✓
probes
✓
target
✓
findings
✓
mx_count
✓
exim_stub
✓
smtp_port
✓
disclaimer
✓
extra_hosts
Always empty in v1 ($2 ≤5 related hosts + CSV + PDF zip is documented follow-up only)
✓
method_note
✓
probe_count
✓
csv_filename
✓
health_grade
✓
opaque_count
✓
postfix_stub
✓
remediations
✓
exchange_stub
✓
nx_local_part
✓
sendmail_stub
✓
egress_blocked
✓
report_markdown
Markdown PASS/WARN/FAIL scorecard: per-MX VRFY/EXPN table, cautious May-allow-enumeration language, postfix/Exim/Sendmail/Exchange disable stubs
✓
change_checklist
✓
pdf_zip_filename
✓
max_probes_per_mx
✓
may_allow_enum_count
What it needs from you
Probe mode (optional)optional
— auto (default), domain (require MX records), or mx (probe this hostname only). Does not change price_usd.
Focus notes (optional)optional
— Echoed in the report (e.g. “postfix cutover — prove every MX disables VRFY/EXPN”). Does not change price_usd.
Public domain or MX hostnamerequired
— One public DNS name you operate. Default auto: resolve MX (preference order) and probe each on TCP :25; if no MX, probe the name as an MX host. Scheme/path stripped. No OAuth. IP-only/internal hosts are out of scope (SSRF fail closed).